Configure cloud environments changedcloud-environments
Nearest release: v2.1.283, published 5 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 26 Sep 2026 00:27 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 28 Sep 2026 23:37 UTC.
Upstream edited
Recorded here
Lines+38added
Lines−38removed
From line
185
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits32to this page, all time
The whole hunk
from line 185, old and new numbered
/
from line 185
185185
186186The **Network access** field in the [environment dialog](#configure-your-environment) takes one of four levels:
187187
188| Level | Outbound connections |
189| :---------- | :------------------------------------------------------------------------------------------- |
190| **None** | No outbound network access through the session's network |
188| Level | Outbound connections |
189| :- | :- |
190| **None** | No outbound network access through the session's network |
191191| **Trusted** | [Allowlisted domains](#default-allowed-domains) only: package registries, GitHub, cloud SDKs |
192| **Full** | Any domain |
193| **Custom** | Your own allowlist, optionally including the defaults |
192| **Full** | Any domain |
193| **Custom** | Your own allowlist, optionally including the defaults |
194194
195195Whichever level you pick, sessions can still reach these, because each one takes a path that doesn't go through the session's network allowlist:
196196
from line 251
251251
252252Cloud sessions start from a fresh clone of your repository. Anything you commit to the repo is available. Anything you've installed or configured only on your own machine isn't available in the session. Your organization's policy arrives separately through [server-managed settings](/docs/en/server-managed-settings).
253253
254| | Available in cloud sessions | Why |
255| :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :--------------------------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
256| Your repo's `CLAUDE.md` | Yes | Part of the clone |
257| Your repo's `.claude/settings.json` hooks and permission rules | Yes, in a session with one repository | Part of the clone. A session with several repositories, including a [project](/docs/en/claude-projects#what-threads-pick-up-from-your-repositories) thread, starts above the clones and doesn't read them |
258| Your repo's `.mcp.json` MCP servers | Yes, in a session with one repository | Part of the clone, found from the session's working directory |
259| Your repo's `.claude/rules/` | Yes | Part of the clone |
260| Your repo's `.claude/skills/`, `.claude/agents/`, `.claude/commands/` | Yes | Part of the clone |
261| Plugins and marketplaces declared in your repo's `.claude/settings.json` | No | A cloud session doesn't install the plugins a repository turns on under [`enabledPlugins`](/docs/en/settings-reference#enabledplugins), including ones from the marketplaces it lists under [`extraKnownMarketplaces`](/docs/en/settings-reference#extraknownmarketplaces) |
262| Your organization's [server-managed settings](/docs/en/server-managed-settings) | Yes | Fetched from Anthropic's servers when the session starts. See [Surface coverage](/docs/en/model-config#surface-coverage) for how `availableModels` is enforced in cloud sessions. Settings deployed to your device through MDM or managed settings files don't apply, because the session runs on an Anthropic-managed VM; in a [self-hosted environment](/docs/en/self-hosted-environments), sessions also read the managed settings file in the runner image, per [how Claude Code combines managed sources](/docs/en/managed-settings#how-claude-code-combines-managed-sources) |
263| Your user `~/.claude/CLAUDE.md` | No | Lives on your machine, not in the repo |
264| Your user `~/.claude/skills/`, `~/.claude/agents/`, `~/.claude/commands/` | No | Live on your machine, not in the repo. Commit them to the repo's `.claude/` directory instead. Cloud sessions automatically load skills you enable on claude.ai |
265| Plugins enabled only in your user settings | No | User-scoped `enabledPlugins` lives in `~/.claude/settings.json` on your machine |
266| MCP servers you added with `claude mcp add` at the default local scope or the user scope | No | Those write to `~/.claude.json` on your machine, not the repo. Add the server with `claude mcp add --scope project`, which writes the repo's [`.mcp.json`](/docs/en/mcp#project-scope), and commit that file. A session with one repository loads it |
267| Transport variables in your repo's `.claude/settings.json` `env` block, such as `NODE_EXTRA_CA_CERTS` and the [mTLS client certificate variables](/docs/en/network-config#mtls-authentication) | No | The hosting environment manages the session's API connection, so Claude Code ignores these keys and notes each ignored key in the session's debug log |
268| API keys and tokens for services Claude calls | On Pro and Max plans, as [API credentials](#add-api-credentials) | You add the key once on the environment and the agent proxy attaches it to requests for the hosts you list. A key the agent proxy [can't attach](#requests-that-never-get-the-credential), or any key on a Team or Enterprise plan, stays in an environment variable |
269| Interactive auth like AWS SSO | No | Not supported. SSO requires browser-based login that can't run in a cloud session |
254| | Available in cloud sessions | Why |
255| :- | :- | :- |
256| Your repo's `CLAUDE.md` | Yes | Part of the clone |
257| Your repo's `.claude/settings.json` hooks and permission rules | Yes, in a session with one repository | Part of the clone. A session with several repositories, including a [project](/docs/en/claude-projects#what-threads-pick-up-from-your-repositories) thread, starts above the clones and doesn't read them |
258| Your repo's `.mcp.json` MCP servers | Yes, in a session with one repository | Part of the clone, found from the session's working directory |
259| Your repo's `.claude/rules/` | Yes | Part of the clone |
260| Your repo's `.claude/skills/`, `.claude/agents/`, `.claude/commands/` | Yes | Part of the clone |
261| Plugins and marketplaces declared in your repo's `.claude/settings.json` | No | A cloud session doesn't install the plugins a repository turns on under [`enabledPlugins`](/docs/en/settings-reference#enabledplugins), including ones from the marketplaces it lists under [`extraKnownMarketplaces`](/docs/en/settings-reference#extraknownmarketplaces) |
262| Your organization's [server-managed settings](/docs/en/server-managed-settings) | Yes | Fetched from Anthropic's servers when the session starts. See [Surface coverage](/docs/en/model-config#surface-coverage) for how `availableModels` is enforced in cloud sessions. Settings deployed to your device through MDM or managed settings files don't apply, because the session runs on an Anthropic-managed VM; in a [self-hosted environment](/docs/en/self-hosted-environments), sessions also read the managed settings file in the runner image, per [how Claude Code combines managed sources](/docs/en/managed-settings#how-claude-code-combines-managed-sources) |
263| Your user `~/.claude/CLAUDE.md` | No | Lives on your machine, not in the repo |
264| Your user `~/.claude/skills/`, `~/.claude/agents/`, `~/.claude/commands/` | No | Live on your machine, not in the repo. Commit them to the repo's `.claude/` directory instead. Cloud sessions automatically load skills you enable on claude.ai |
265| Plugins enabled only in your user settings | No | User-scoped `enabledPlugins` lives in `~/.claude/settings.json` on your machine |
266| MCP servers you added with `claude mcp add` at the default local scope or the user scope | No | Those write to `~/.claude.json` on your machine, not the repo. Add the server with `claude mcp add --scope project`, which writes the repo's [`.mcp.json`](/docs/en/mcp#project-scope), and commit that file. A session with one repository loads it |
267| Transport variables in your repo's `.claude/settings.json` `env` block, such as `NODE_EXTRA_CA_CERTS` and the [mTLS client certificate variables](/docs/en/network-config#mtls-authentication) | No | The hosting environment manages the session's API connection, so Claude Code ignores these keys and notes each ignored key in the session's debug log |
268| API keys and tokens for services Claude calls | On Pro and Max plans, as [API credentials](#add-api-credentials) | You add the key once on the environment and the agent proxy attaches it to requests for the hosts you list. A key the agent proxy [can't attach](#requests-that-never-get-the-credential), or any key on a Team or Enterprise plan, stays in an environment variable |
269| Interactive auth like AWS SSO | No | Not supported. SSO requires browser-based login that can't run in a cloud session |
270270
271271To make your own configuration available in cloud sessions, commit it to the repo.
272272
from line 276
276276
277277Cloud sessions come with common language runtimes, build tools, and databases pre-installed. The table below summarizes what's included by category.
278278
279| Category | Included |
280| :------------ | :------------------------------------------------------------------------- |
281| **Python** | Python 3.x with pip, poetry, uv, black, mypy, pytest, ruff |
282| **Node.js** | 20, 21, and 22, with npm, yarn, pnpm, bun¹, eslint, prettier, chromedriver |
283| **Ruby** | 3.1, 3.2, 3.3 with gem, bundler, rbenv |
284| **PHP** | 8.3 with Composer |
285| **Java** | OpenJDK 21 with Maven and Gradle |
286| **Go** | Go with module support |
287| **Rust** | rustc and cargo |
288| **C/C++** | GCC, Clang, cmake, ninja, conan |
289| **Docker** | docker, dockerd, docker compose |
290| **Databases** | PostgreSQL 16, Redis 7.0 |
291| **Utilities** | git, gh, jq, yq, ripgrep, tmux, vim, nano |
279| Category | Included |
280| :- | :- |
281| **Python** | Python 3.x with pip, poetry, uv, black, mypy, pytest, ruff |
282| **Node.js** | 20, 21, and 22, with npm, yarn, pnpm, bun¹, eslint, prettier, chromedriver |
283| **Ruby** | 3.1, 3.2, 3.3 with gem, bundler, rbenv |
284| **PHP** | 8.3 with Composer |
285| **Java** | OpenJDK 21 with Maven and Gradle |
286| **Go** | Go with module support |
287| **Rust** | rustc and cargo |
288| **C/C++** | GCC, Clang, cmake, ninja, conan |
289| **Docker** | docker, dockerd, docker compose |
290| **Databases** | PostgreSQL 16, Redis 7.0 |
291| **Utilities** | git, gh, jq, yq, ripgrep, tmux, vim, nano |
292292
293293¹ Bun is installed but has known [proxy compatibility issues](#install-dependencies-with-a-sessionstart-hook) for package fetching.
294294
from line 413
413413
414414Setup scripts and SessionStart hooks run in a fixed order when a cloud session starts. The table compares where you configure them, when they run, and where they run.
415415
416| | Setup scripts | SessionStart hooks |
417| ---------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
416| | Setup scripts | SessionStart hooks |
417| - | - | - |
418418| **Where you configure them** | The environment dialog at [claude.ai/code](https://claude.ai/code), plus the **Cloud environments** admin page for [shared environments](#organization-shared-environments) | A [settings file](/docs/en/settings#where-settings-live) such as your repo's `.claude/settings.json`; see [What carries over from your setup](#what-carries-over-from-your-setup) for which files reach a cloud session |
419| **When they run** | Before Claude Code launches, skipped when a [cached environment](#environment-caching) exists | After Claude Code launches, on every session including resumed |
420| **Where they run** | Cloud sessions only | Local and cloud sessions |
419| **When they run** | Before Claude Code launches, skipped when a [cached environment](#environment-caching) exists | After Claude Code launches, on every session including resumed |
420| **Where they run** | Cloud sessions only | Local and cloud sessions |
421421
422422If you have SessionStart hooks in your user-level `~/.claude/settings.json`, don't expect them in the cloud. User-level settings stay on your machine. Which other hooks run depends on where the session runs:
423423
No line in this hunk matches that.